CVE-2015-2994
08.06.2015, 14:59
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by uploading a file with a .jsp extension, then accessing it via a direct request to the file in icons/user_photo/.Enginsight
Vendor | Product | Version |
---|---|---|
sysaid | sysaid | 𝑥 ≤ 15.1 |
𝑥
= Vulnerable software versions
References